What is CVE-2026-13723?
This critical vulnerability in the `zipx.Unzip` extraction routine of Develar's app-builder allows attackers to overwrite arbitrary files on macOS APFS by exploiting a Unicode Normalization Collision combined with symlink following behavior. Developers using app-builder should immediately update and restrict extraction of archives from untrusted sources.
Azərbaycanca: Bu kritik zəiflik `zipx.Unzip` funksiyasında macOS APFS fayl sistemində Unicode Normallaşdırma Toqquşması və simvolik keçid izləmə davranışından istifadə edərək ixtiyari fayl üzərindən yazmağa imkan verir. Develar-ın `app-builder` proqramını istifadə edən tərtibatçılar təsirlənə bilər; dərhal yeniləmə tətbiq edilməli və etibarsız mənbələrdən gələn arxiv fayllarının çıxarılması məhdudlaşdırılmalıdır.
Related CVEs
link basis: same weakness class CWE-22
FAQ2
On which operating system does CVE-2026-13723 pose a specific threat?
This critical vulnerability is particularly dangerous on macOS APFS because it exploits a Unicode Normalization Collision combined with symlink following behavior.
Which Develar product is vulnerable to CVE-2026-13723?
Developers using Develar's app-builder are potentially affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.